IInsurAGI
Comment ça marcheFonctionnalitésTarifsGuide d'assuranceBlogÀ propos
Comment ça marcheFonctionnalitésTarifs

Guides

Guide d'assurance
BlogÀ propos

IInsurAGI

Des conseils en assurance indépendants propulsés par l'IA. Nous vous aidons à optimiser votre protection.

Produit

  • Accueil
  • Comment ça marche
  • Fonctionnalités
  • Tarifs

Ressources

  • À propos
  • Blog
  • Guide d'assurance
  • Questions des utilisateurs
  • Sécurité

Mentions légales

  • Conditions d'utilisation
  • Politique de confidentialité
  • Politique des cookies
  • Utilisation acceptable
  • Sitemap
InsurAGI AB·Org.nr: 559430-3397·Hornsgatan 29 e, 118 49 Stockholm, Sweden

© 2026 InsurAGI. Tous droits réservés.

Sécurisé et chiffré
Privacy

Integrity Policy for Protection of Personal Data

Last updated: August 21, 2026. We respect your privacy and explain here how we process personal data, what we collect, why, with whom we share it, how we protect it and the choices you can make.

We respect your privacy. In this integrity policy for the protection of personal data (hereinafter referred to as the ”Policy”), we describe how we process personal data, which personal data we collect, why we collect it, with whom we share the personal data, how we protect it and which choices you can make with respect to our processing of your personal data.

The Policy is applicable on all personal data as defined below collected, stored or processed by or on behalf of InsurAGI AB, reg. no. 559430-3397 (the “Company”, “we” or “us”) which has a connection to a specific individual in his/her relations with the Company as a customer, consumer or which is available in the public domain. The Company is responsible for the processing of personal data. InsurAGI does not share individual user data with group companies for product development, model improvement, analytics, support or commercial purposes.

The Policy also includes all websites or mobile websites owned by the Company where personal data is processed, such as www.insuragi.com (such website, together with any other website owned by the Company, is hereinafter collectively referred to as the “Website”).

The InsurAGI service is intended for users who are at least 18 years old. We use an age gate. Adults may upload household insurance documents that include information about family members, including children, only where this is necessary for the relevant insurance analysis. You must not upload third-party personal data unless it is necessary for your insurance matter and you have the right to share it with us.

The requirements and guidelines stipulated in this Policy are a supplement to applicable laws and regulations on protection of personal data and does not intend to replace any such applicable laws or regulations on protection of personal data. In the event of a conflict between applicable laws and regulations on protection of personal data and the requirements and guidelines in this Policy, the applicable laws or regulations on protection of personal data shall prevail.

The Company can amend this Policy at any time. It is recommended that you read this Policy from time to time via the Website in order to be updated in relation to any amendments to this Policy.

1. Definitions

1.1In this Policy, a number of definitions are used. They have the following meanings:

(a)Processing: means any operation or set of operations performed on personal data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

(b)EEA: means the European Economic Area (consisting of the countries being members in the EU, plus Iceland, Liechtenstein and Norway).

(c)Personal Data: means any information relating to an identified or identifiable living individual. An identifiable person is one who can be identified, directly or indirectly, by reference to identifiers such as name, identification number, location data, online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity. A description of which Personal Data that is processed by the Company can be found in Section 3 below.

2. Main Principles in the Policy

2.1We appreciate to be given the confidence to process Personal Data and we are determined to process them in a correct, transparent and secure manner. We have, inter alia, the following main principles in our Policy:

  • Lawfulness, fairness and transparency: We process Personal Data only where we have a lawful basis and we aim to explain our processing in a clear and accessible way.
  • Purpose limitation: We collect and use Personal Data only for specified, explicit and legitimate purposes described in this Policy.
  • Data minimisation: We limit the Personal Data we collect and process to what is necessary and relevant for the purposes described in this Policy.
  • Accuracy: We take reasonable steps to keep Personal Data accurate and up to date where necessary.
  • Storage limitation: We do not keep Personal Data for longer than necessary for the relevant purposes, unless a longer retention period is required or permitted by law.
  • Security, integrity and confidentiality: We use appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage.
  • Third-party access: We only give third parties access to Personal Data where this is necessary for the purposes described in this Policy and subject to appropriate safeguards.
  • Direct communications and cookies: We send direct communications and use cookies or similar technologies only in accordance with applicable law, this Policy and our Cookie Policy.

3. Collection of Data

3.1We may collect Personal Data directly from you, automatically when you use the Website, App or service, and from service providers used to operate the service. The categories of Personal Data we may process include:

CategoryExamples of Personal Data
Account and contact dataName, email address, login/account identifiers, age confirmation, settings, subscription status and communications with us.
Insurance documents and insurance contentUploaded insurance policies, IPIDs, insurance letters and other documents you choose to upload, plus information extracted from those documents, such as insurer, product, cover, exclusions, limits and dates.
Questions, prompts and AI outputFree-text questions, scenario descriptions, prompts, answers, chat history and related metadata needed to operate the service.
Derived service dataDocument matches, policy tags, coverage findings, duplicate-cover findings, summaries, cached context, InsurAGI Score and similar user-visible service results.
Technical retrieval dataWhere needed for retrieval or indexing, the service may create technical indexes or embeddings linked to your documents/account. We treat these as personal data where they can be linked to you or your documents.
Sensitive data you choose to provideInsurance documents or scenario descriptions may include health data, accident or medical information, disability information or other special-category data. We ask you not to include more sensitive data than necessary.
Children and third-party data in documentsHousehold documents may include data about children or other people, such as family members, witnesses, claim handlers, counterparties, employers or other persons.
Usage, device and security dataIP address, device/browser information, timestamps, login and session events, security logs, audit logs, support-access logs and limited technical metadata.
Payment and subscription dataSubscription status and limited payment metadata in our system. Stripe handles card details and most payment/fraud/regulatory processing.
Analytics and cookiesCookie consent state, language preference, landing-page analytics after consent, and cookieless performance telemetry where applicable. See our Cookie Policy.
Support dataSupport requests, beta feedback, bug reports, messages, survey responses, troubleshooting information and support-access records. Depending on the Gleap configuration and the feedback function used, this may also include contact details, screenshots or screen recordings, attachments, session identifiers, approximate country, device/browser and operating-system information, console or network logs, replay data and custom metadata. We do not expect support or beta cases to contain sensitive insurance or health content unless you include it or a case requires escalation.

3.2We do not intentionally collect full payment card details. Payments are handled through our payment provider, Stripe. We may process limited billing, subscription, payment status and transaction-related information necessary to administer your subscription and comply with accounting obligations.

3.3We do not knowingly allow individuals under 18 to create an account or use the service directly. However, adults may upload household insurance documents that include information about children or other family members where this is necessary for the requested insurance analysis.

4. Why Does the Company Need Your Personal Data?

4.1The Company processes your Personal Data for the following purposes (hereinafter referred to collectively as the ”Purposes” and each individually as a “Purpose”):

(a)Core service: To create and manage your account, receive and store uploaded insurance documents, extract relevant information, answer questions, provide document-supported explanations and make user-visible findings available to you.

(b)Request for information and support: To answer your questions, effectuate your requests, provide support, manage support cases, investigate bug reports, evaluate beta features and feedback, troubleshoot issues and handle justified escalations.

(c)Newsletters and direct communications: To send newsletters or other communications that you have requested or subscribed to. You can unsubscribe at any time.

(d)Website analytics: To analyse use of public marketing and landing pages where you have consented to analytics cookies. Google Analytics is not used in logged-in service areas, document views or AI chats.

(e)Security, fraud prevention and system protection: To protect accounts, documents, systems, intellectual property rights, economic and financial interests, and the integrity of users and employees.

(f)IT-support and development: To operate, maintain, secure, debug and develop the service, including investigating specific support cases, bug reports and beta feedback submitted through Gleap. For a specific case, we may use the submitted feedback and related diagnostic data to reproduce and resolve the issue or evaluate the beta feature. Broader product improvement is carried out using synthetic data and anonymised or aggregated information, not raw customer documents, prompts, chat content or unrelated individual user data.

(g)Compliance with laws and legal requirements: To comply with laws and regulations and to establish, exercise or defend legal claims.

(h)Aggregated or anonymized statistics: To create robustly aggregated or anonymised statistics that do not identify individual users, for example for internal analysis or partner reporting.

(i)Payments and subscription administration: To manage subscription status, payment flow, billing metadata, accounting and related administration through Stripe and our internal systems.

(j)Corporate transactions: To prepare and carry out a consolidation, joint venture, acquisition, divestment or transfer of Personal Data, assets, all or part of the stock in the Company or the Company’s business, or any other ownership change, reorganization or corporate transaction (including financing of the Company or financing of any part of the corporate events mentioned in this sub-paragraph).

(k)Other communicated purposes: Any other purpose that has been described and communicated to you before your Personal Data is used for such other purpose.

4.2The Company may only process Personal Data to the extent necessary to achieve the relevant Purpose and for other purposes that are explicitly permitted pursuant to applicable laws or regulations on protection of Personal Data.

5. The Service and the Role of AI, AI Providers, Document Segmentation and No-Training

5.1At launch, the service lets users upload insurance documents and ask questions about existing insurance cover. The AI output is intended to provide document-supported explanations, clause references, neutral next steps and general process guidance. It is not intended to provide insurance mediation, personal financial advice, legal advice or claims decisions.

5.2You may ask questions such as whether a situation appears to be covered. The answer should be cautious, conditional and tied to the relevant policy wording. The service does not decide whether you are entitled to compensation, does not affect your price, terms, access to insurance or claims process, and does not send output automatically to insurers, unions, employers or other partners.

5.3Where the service displays an InsurAGI Score or similar findings, the score measures analysis basis and coverage clarity. It is not a score of your personal insuranceworthiness, risk level, health, claims outcome or objective value as a policyholder. User-level scores, coverage gaps, duplicate-cover findings and similar findings are user-visible, minimal, exportable and deletable.

5.4The service uses Microsoft Azure/OpenAI for LLM/API functionality. When technically necessary to answer your question, relevant excerpts or segments from uploaded documents and minimised metadata may be sent to the LLM provider. Full documents are sent only where local extraction or segmentation is insufficient for the requested function.

5.5Customer data is not used by InsurAGI or by the LLM provider for model training or fine-tuning. Broader product improvement, evaluation and quality testing are carried out using synthetic data and anonymised or aggregated data, not raw customer documents or chat content. Specific support or beta-testing cases may nevertheless require authorised personnel to use the feedback and diagnostic data submitted for that case to investigate, reproduce and resolve the reported issue.

5.6Where technical retrieval or indexing creates embeddings or similar artefacts, they are stored in an EU/EEA-controlled environment, treated as personal data where linkable, and deleted when the source document is deleted.

6. Special-Category Data, Health Data and Consent

6.1Insurance material may sometimes reveal health, accident, disability, medical or other special-category information. You should only upload or type sensitive information when it is necessary for the insurance analysis you request. We may provide warnings or separate consent steps before such information is processed.

6.2Where we rely on explicit consent under Article 9(2)(a) GDPR for special-category data, you can withdraw that consent. Withdrawal does not affect processing already carried out, but future processing of the relevant sensitive data will stop. Uploaded sensitive documents and derived data will be deleted or restricted unless a concrete legal hold or legal obligation requires limited continued storage.

6.3We do not use health data, children’s data, claims history or other sensitive information to train AI models, to build marketing audiences, to score your insuranceworthiness or to share individual results with partners.

7. Data Controller

7.1The Company is the data controller for all processing of Personal Data that the Company, or any other party on behalf of the Company, conducts if not otherwise stipulated in this Policy.

7.2The Company has not appointed a specific Data Protection Officer.

8. Legal Basis

8.1We use purpose-specific legal bases. We do not rely on general “consent by using the service” for all processing.

PurposeWhat this includesLegal basis
Provide the core serviceCreate and manage your account; receive uploaded documents; extract relevant text; match documents to generic policy-condition data; answer questions; store your documents, chat history, prompts, outputs and derived user-visible findings so the service works for you.Article 6(1)(b) GDPR: necessary to perform the user agreement.
Process health data or other special-category data you choose to upload or typeHandle sensitive information in insurance documents or scenario descriptions where this is necessary for your requested analysis.Article 6(1)(b) GDPR and Article 9(2)(a) GDPR: explicit consent for special-category data. You may withdraw this consent.
Support and beta testingRespond to support requests; investigate bug reports; evaluate voluntary beta feedback; reproduce and resolve issues affecting the service; and communicate with the person who submitted the case.Article 6(1)(b) GDPR for service-related support. Article 6(1)(f) GDPR for bug investigation, beta evaluation and limited operational and security measures connected to support, based on our and users' legitimate interests in improving and securing the service. Where a specific optional collection feature legally requires consent, Article 6(1)(a) GDPR.
Security, fraud prevention and system protectionProtect accounts, documents and systems; log access; detect abuse; scan uploads for malware; reduce prompt-injection and security risks; investigate incidents.Article 6(1)(f) GDPR: our and users’ legitimate interests in secure operation of the service.
Payments and subscription administrationManage subscription status and payment flow via Stripe.Article 6(1)(b) GDPR. For accounting, tax and bookkeeping records: Article 6(1)(c) GDPR.
Accounting and legal complianceKeep records required by law and handle regulatory or legal requests.Article 6(1)(c) GDPR where required by law; Article 6(1)(f) GDPR where necessary to establish, exercise or defend legal interests.
Analytics on public marketing/landing pagesMeasure high-level website usage on public pages after your cookie consent. Google Analytics is not used in logged-in service areas, document views or AI chats.Consent for non-essential cookies and related analytics; Article 6(1)(a) GDPR where analytics involves personal data.
Product improvementImprove the service using synthetic data and anonymised or aggregated information. Uploaded documents, prompts, chat content and individual user data are not used for model training, fine-tuning or marketing.No personal data basis is required for truly anonymised data. If personal data is ever proposed for improvement, a separate legal basis and notice would be required.
Direct communications you requestSend newsletters or other communications you subscribe to.Consent or other applicable lawful basis depending on the specific communication. You can unsubscribe at any time.

8.2You can withdraw any consent (e.g. to newsletters or non-essential cookies) at any time without affecting processing already done.

9. Correctness of Personal Data

9.1It is important to us that your Personal Data is updated and correct. Please inform us of any changes to, or inaccuracies in, your Personal Data as soon as possible. We will do our best to make sure that inaccurate or obsolete Personal Data is deleted, destroyed or corrected. If you believe that the Personal Data we have about you is inaccurate or obsolete, you are entitled to request that our processing of Personal Data is limited while we control if the relevant Personal Data is correct or incorrect.

10. Data Retention

10.1We store Personal Data only for as long as necessary for the purposes described in this Policy. Different categories of data have different retention periods, as outlined in the table below:

Data typeRetention
Account dataFor as long as the account is active and thereafter for 90 days before deletion or restriction, unless a legal obligation or concrete legal hold requires longer limited storage.
Uploaded documentsFor as long as the account is active and thereafter for 90 days before deletion or restriction. You can delete individual documents earlier.
Chat historyFor as long as the account is active and thereafter for 90 days before deletion or restriction. You can delete chat history earlier.
Prompts and outputsFor as long as the account is active and thereafter for 90 days before deletion or restriction.
Embeddings/retrieval indexesSame lifecycle as the source document. They are deleted when the source document is deleted.
Derived artefactsSame lifecycle as the underlying data unless a specific user-facing feature requires retention; they are deleted with the underlying data.
Support and beta-feedback cases12 months after account closure. Beta feedback connected to an account follows the same period. Sensitive attachments in support or beta feedback should be avoided and may be deleted sooner unless a dispute, legal hold or security need requires limited storage.
Payment/accounting dataSubscription status is kept as long as needed for the subscription. Accounting records are kept according to Swedish bookkeeping rules, normally seven years after the calendar year in which the financial year ended. Stripe determines retention for payment data it controls.
Analytics raw data14 months. Aggregated or anonymised statistics may be kept longer.
Security logsSecurity and API logs are retained only for as long as necessary for security, fraud prevention, accountability, incident investigation, audit and legal purposes. Retention is applied by log type and may be up to approximately 12 months where necessary. Shorter retention is used where sufficient. Longer limited retention may apply where required for a specific incident, suspected misuse, legal request, dispute or concrete legal hold.
BackupsBackups follow documented rotation, expiry and restore controls. Current production database backups are retained through AWS RDS automated backups for 14 days. Other backups, snapshots or recovery copies, if used, follow their documented schedules and normally expire within the applicable backup rotation period. Deleted data may remain in backups until backup expiry, but backups are not used for ordinary processing or to reintroduce deleted personal data into active systems except where necessary for continuity, disaster recovery, security investigation, legal obligation, incident response or a concrete legal hold.

10.2Where a document is deleted, related extracted text, embeddings and derived artefacts that remain linkable to the document or user will also be deleted or de-linked in accordance with the applicable deletion process, unless continued limited retention is required by law or a concrete legal hold.

11. Data Security

11.1We ensure that technical and organizational measures are taken in order to prevent unlawful or disallowed processing of Personal Data and also other incorrect usage, destruction, disclosure, acquisition of and loss of Personal Data in the event of an accident. Personal Data may only be processed by a third party that is a Personal Data processor if such Personal Data processor undertakes to comply with the aforementioned technical and organizational security measures.

11.2Maintenance of data security entails guaranteeing non-disclosure, integrity and access to the Personal Data:

(a)Non-disclosure: We protect your Personal Data so that it is not unlawfully disclosed to a third party.

(b)Integrity: We protect your Personal Data so that it is not unlawfully amended by an unauthorized third party.

(c)Access: We ensure that authorized third parties, if necessary and lawful, will be given access to your Personal Data.

11.3In the security measures, the following elements are included:

(a)Risk analysis and risk assessment:

(b)Organization and human aspects of security: classing of information, information and education of employees, disciplinary actions upon violations of the rules, employees’ awareness of the importance of non-disclosure, effects on outsourcing agreements;

(c)Physical security and environmental security: ensure physical access, prevent and discover/handle physical hazards (fire, water, etc.), backup-systems;

(d)Network security: availability security, list of involved employees, authentication systems;

(e)Access logs, tracking and analysis;

(f)Supervisory actions, judgments and maintenance;

(g)Handling of security incidents and continuity: surveillance systems for security contingencies, preparation of incident/catastrophy plan, continuity plan; and

(h)Complete and updated documentation.

11.4For the InsurAGI service, access to production data is limited to authorised personnel with a justified need. Support and beta-testing personnel may access a Gleap case and related diagnostic data only where needed to respond, reproduce a reported issue, evaluate a beta feature or handle a justified escalation. Access by support or development personnel to uploaded documents or full chat history is not routine and is intended to be case-based, just-in-time and logged. We also use measures such as EU/EEA-controlled infrastructure, access controls, audit logging, upload/security checks and incident-handling routines appropriate to the sensitivity of the data.

11.5In the unlikely event of a personal data breach, we will notify affected individuals and the Swedish Data Protection Authority (IMY) as required by law.

12. Sharing Personal Data

12.1We may share Personal Data only where necessary for the purposes described in this Policy and subject to appropriate contractual, technical and organisational safeguards. The relevant categories of recipients are set out below.

12.2Who receives Personal Data:

Recipient/categoryRole or reason
AWS Ireland / EU-EEAHosting, file storage, databases, logs, monitoring/security and EU/EEA infrastructure.
Microsoft Azure/OpenAILLM/API functionality needed to generate document-supported answers. No training on customer data.
Mistral AI SAS (France)File/OCR/parsing functionality in the EU/EEA region.
Stripe Technology Europe Limited (Ireland)Payment and subscription processing. Stripe may act as an independent controller for some payment, fraud-prevention and regulatory processing. InsurAGI does not store card details.
Google Ireland LimitedEmail/CRM and Google Analytics on public landing pages after consent. Google Analytics is not used in logged-in service areas.
Pebium / external development partnerDevelopment/production-environment access only where required and subject to role-based controls, just-in-time access and logging.
Gleap GmbH (Austria)Personal Data processor providing support-case management, in-product feedback, beta testing, bug reporting and related communications and diagnostics. The data processed depends on the enabled functions and may include messages, contact details, screenshots or attachments, session identifiers, device/browser metadata, console or network logs and replay data.
Support personnelNo routine access to uploaded documents or full chat history. Access is case-based, just-in-time and logged, for support requests, security incidents or other justified escalation.
Unions/partnersNo individual user data in the standard setup. Robustly aggregated/anonymised statistics may be shared. Partners do not see which members use the service unless a separate scenario and notice says otherwise.
Authorities or legal recipientsOnly where required by law or necessary to protect legal interests.

12.3We do not sell Personal Data. We do not share individual user documents, prompts, chat history, AI outputs, health data, claims information or user-level findings with insurers, unions, employers, group companies or commercial partners for their own marketing, underwriting, pricing, claims-handling, product-development or analytics purposes, unless you specifically instruct us to do so or we are legally required.

12.4Some recipients, such as Stripe or Google in relation to certain services, may act as independent controllers for specific processing they carry out under their own legal obligations or service terms. Where that is the case, their own privacy information applies to that independent processing.

13. Disclosure Outside the EU/EEA

13.1According to the current architecture, primary data, files/documents, databases, logs, backups and embeddings/vector database storage are in Ireland within the EU/EEA region. Gleap states that its primary infrastructure is hosted in the EU, but its current sub-processor chain includes providers established or operating outside the EU/EEA. Depending on the enabled Gleap functions and the type of case, support and beta-feedback data may therefore be processed in third countries, including for transactional email delivery, global content delivery or storage, and optional AI features. We configure and use Gleap subject to the safeguards described below.

13.2If a transfer of personal data outside the EU/EEA becomes necessary, we will use an appropriate transfer mechanism, such as an adequacy decision or the EU Standard Contractual Clauses, together with a transfer impact assessment and supplementary measures where required.

14. Your Rights

14.1Your Personal Data: You may contact us by post or email to request information about whether we process Personal Data concerning you and, where applicable, to receive access to such Personal Data and information about, inter alia, the purposes of the processing, the categories of Personal Data concerned, the recipients or categories of recipients, the retention period or criteria used to determine that period, and, where the Personal Data has not been collected directly from you, any available information about its source.

14.2Your consent: If any processing of Personal Data is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

14.3Your objections: You may object to processing of your Personal Data where the processing is based on our legitimate interests. You may always object to the processing of your Personal Data for direct marketing purposes, including any related profiling. If you object to direct marketing, we will no longer process your Personal Data for such purposes. Objections to direct marketing may also be made through the unsubscribe or preference settings included in the relevant marketing material.

14.4Data portability: Where the processing is based on your consent or on a contract with you and is carried out by automated means, you may request to receive the Personal Data that you have provided to us in a structured, commonly used and machine-readable format. Where technically feasible, you may also request that such Personal Data is transmitted directly to another controller.

14.5Right to rectification: If you believe that there are inaccuracies in your Personal Data, or that they are incomplete, you may also request that we change or supplement such incomplete or incorrect Personal Data.

14.6Right to erasure: You can also require that we delete information about you, where the conditions for erasure under applicable data protection laws are met (however, excluding information that are verifications of a transaction or information we are required to maintain pursuant to any law or regulation). You can also request that we restrict processing of your Personal Data in certain cases (e.g. if you contest accuracy while we verify it) instead of immediate deletion.

14.7Automated decisions: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. The InsurAGI service is not designed to make such decisions.

14.8Requests to exercise your rights under this Section shall be directed to the Company at info@insuragi.com. Objections pursuant to Section 14.3 may also be presented through using the unsubscription preference settings in the marketing material.

15. Amendments

15.1The Company is entitled to amend this Policy by posting an updated Policy including relevant amendments at the Website. The amendments will come into force with immediate effect.

16. Contacts and Complaints

16.1The Company is the data controller. In any matter involving secrecy, questions or complaints in relation to this Policy or in relation to the exercise of any of your rights under this Policy, you may contact the Company at info@insuragi.com.

16.2Complaints on the Company’s Personal Data processing may also be set forth to the Swedish Authority for Privacy Protection (Sw. Integritetsskyddsmyndigheten) (the “IMY”) at email-address imy@imy.se or postal address Integritetsskyddsmyndigheten, P.O. Box 8114, 104 20 Stockholm, Sweden. The IMY recommends that any complaints shall include the following information: (i) the subjects of the complaint, (ii) what the customer is dissatisfied with (as detailed as possible), (iii) description of what has happened and when, and (iv) copies, pictures or printouts of what the customer is complaining about.